MgoSync – European dropshipping and suppliers Security & Risk Analysis

wordpress.org/plugins/megamo

Grow your store by importing products from the suppliers of your choice and keeping them up-to-date. Request your integration today!

30 active installs v2.1.6 PHP 7.0+ WP 4.4+ Updated Dec 5, 2024
dropshipdropshippingintegrationproductswoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MgoSync – European dropshipping and suppliers Safe to Use in 2026?

Generally Safe

Score 92/100

MgoSync – European dropshipping and suppliers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'megamo' plugin version 2.1.6 exhibits a mixed security posture. On one hand, it demonstrates good practices by having no known CVEs, no unpatched vulnerabilities, and a clean vulnerability history, which is a strong positive indicator. The static analysis reveals no critical or high severity taint flows, and all SQL queries are properly prepared, which are excellent security measures.

However, there are significant concerns that temper this positive outlook. The lack of any nonce checks or capability checks across all entry points is a major red flag. Coupled with 2 flows identified with unsanitized paths, this suggests a substantial risk of arbitrary code execution or privilege escalation if an attacker can find a way to trigger these flows. Furthermore, the output escaping is only at 24%, indicating a high potential for cross-site scripting (XSS) vulnerabilities across a significant portion of the plugin's outputs.

In conclusion, while 'megamo' v2.1.6 is free from historical vulnerabilities and uses secure SQL practices, the complete absence of authentication and authorization checks on its entry points, along with widespread unescaped output and unsanitized path flows, creates a high-risk profile. These fundamental security weaknesses could easily be exploited, especially given the presence of unsanitized path data. The plugin's strength in vulnerability history is overshadowed by critical flaws in its current implementation.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • Low percentage of properly escaped output (24%)
  • 2 flows with unsanitized paths
Vulnerabilities
None known

MgoSync – European dropshipping and suppliers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MgoSync – European dropshipping and suppliers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
37
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
9
External Requests
1
Bundled Libraries
0

Output Escaping

24% escaped49 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
viewSuppliers (includes\views\components\suppliers.php:11)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MgoSync – European dropshipping and suppliers Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionrest_api_initincludes\class-mgosync-api.php:32
actionadmin_enqueue_scriptsincludes\class-plugin.php:217
actionadmin_enqueue_scriptsincludes\class-plugin.php:218
actionadmin_menuincludes\class-plugin.php:224
actionadmin_menuincludes\class-plugin.php:225
actionmgo_dashboard_hookincludes\class-plugin.php:226
actionmgo_dashboard_hookincludes\class-plugin.php:228
actionmgo_dashboard_hookincludes\class-plugin.php:229
Maintenance & Trust

MgoSync – European dropshipping and suppliers Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 5, 2024
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

MgoSync – European dropshipping and suppliers Developer Profile

Megamo

2 plugins · 30 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MgoSync – European dropshipping and suppliers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/megamo/js/mgo-scripts.js/wp-content/plugins/megamo/css/mgo-styles.css
Script Paths
/wp-content/plugins/megamo/js/mgo-scripts.js

HTML / DOM Fingerprints

Data Attributes
mgo-logo-svgdashboardCtrlcontactUsCtrlbrowseSuppliersCtrlaboutUsCtrlsettingsCtrl
FAQ

Frequently Asked Questions about MgoSync – European dropshipping and suppliers